go to NIST home page go to CSRC home page go to Focus Areas page go to Publications page go to Advisories page go to Events page go to Site Map page go to ITL home page CSRC home page link
header image with links

HOME
 
Federal Agency
Security Practices (FASP)

 
    Pilot BSPs
 
    FAQ
 
    Federal Computer
    Security Program
    Managers' Forum
 
Public/Private
Security Practices
 
DISA Security
Technical
Implementation

Guides (STIGS)
 
Submit Practices
& Checklists/
Implementation
Guides

 
Points of Contacts

Information Technology Security
Public / Private Security Practices

Public / Private Security Practices

File Format

Date Posted

Some security practices in the listing below may not reference an organization's affiliation. These practices are provided in a generic format. The second column specifies the type of file format (Ex. MS Word, pdf, Text file, etc.) that the file is available in. The third column contains the date when the file was posted to this page.
 

   

NIST invites public and private organizations to submit their information security practices as nominated candidates for inclusion in its Computer Security Resource Center. With the recognition that protection of the Nation's critical infrastructure is dependent upon effective information security solutions and to minimize vulnerabilities associated with a variety of threats, the broader sharing of such practices will enhance the overall security of the nation. Today's federal networks and systems are highly interconnected and interdependent with non-federal systems. Access to information security practices in the public and private sector can be applied to enhance the overall performance of Federal information security programs.

Nominated candidate policies and procedures may be submitted to NIST in any area of information security including, but not limited to: accreditation, audit trails, authorization of processing, budget planning and justification, certification, contingency planning, data integrity, disaster planning, documentation, hardware and system maintenance, identification and authentication, incident handling and response, life cycle, network security, personnel security, physical and environmental protection, production input/output controls, security policy, program management, review of security controls, risk management, security awareness training, and education (to include specific course and awareness materials), and security planning.
 

PUBLIC SECURITY PRACTICES -
Common Risks Impeding the Adequate Protection of Government Information: Sponsored by DHS and OMB
 
  07/13/07
CIO Council
 
 
05/28/03
Felix Uribe's List of the Best 100 Websites in Computer and Information Security
 
11/18/04
General Accounting Office
 
06/23/03
Information Assurance Technical Framework Forum (IATFF)
 
09/04/03
Lessons Learned by Consumers, Financial Sector Firms, and Government Agencies during the Recent Rise of Phishing Attacks - May 2004
 
.pdf file
06/14/04
The Internet Engineering Task Force (IETF)
 
09/04/03
U.S. Department of Defense: Information Assurance Technology Analysis Center
 
07/15/03
U.S. Department of Energy Computer Incident Advisory Capability (CIAC)
 
03/15/04
PRIVATE SECURITY PRACTICES -
2004 Resource Guide for Today's U.S. Government Information Security Professional
 
 
04/07/04
American Bankers Association (ABA Fraud Solutions and Resources)
 
 
09/09/04
American Bankers Association (Sample Bank Privacy Policies)
 
 
09/09/04
Ars Technica (Wireless Practicum: Essential Home Wireless Security Practices, Part 1)
 
 
09/10/04
Ars Technica (Wireless Practicum: Essential Home Wireless Security Practices, Part 2)
 
 
09/10/04
Internet Security Task Force
 
 
08/18/03
Microsoft
 
 
09/10/04
SANS Institute
 
 
09/10/04
Workgroup for Electronic Data Interchange - Strategic National Implementation Process
 
 
04/07/04
 
ACADEMIA SECURITY PRACTICES -
Carnegie Mellon University CERT® Coordination Center
 
 
09/09/03
EDUCAUSE
 
 
09/10/04
 
 

 

 :

Last updated: July 13, 2007
Page created: May 27, 2003

Disclaimer Notice & Privacy Policy
Send comments or suggestions to infosecpractices@nist.gov
NIST is an Agency of the U.S. Commerce Department's
Technology Administration